# Latest

**URL:** https://discuss.elastic.co/latest.md?page=717

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 718

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/329632)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 24\
**Last updated:** [April 10, 2023, 8:02pm UTC](https://discuss.elastic.co/t/elasticsearch/329632 "2023-04-10T20:02:57Z")

</div>

HI I I want to run the container of elasticsearch : i use this command docker run --name es01 --net elastic -p 9200:9200 -it docker.elastic.co/elasticsearch/elasticsearch:8.2.3 and this : docker cp es01:/usr/share/e…

---

## [Storage Configuration Question](https://discuss.elastic.co/t/storage-configuration-question/329675)

<div class="topic-metadata">

**Author:** [@Safty](https://discuss.elastic.co/u/Safty)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 8:00pm UTC](https://discuss.elastic.co/t/storage-configuration-question/329675 "2023-04-10T20:00:21Z")

</div>

Hello, In the storage documentation link There is a reference in the path.data section that states the following: "Elasticsearch requires the filesystem to act as if it were backed by a local disk, but this means that…

---

## [Can't get filebeat to read filestream](https://discuss.elastic.co/t/cant-get-filebeat-to-read-filestream/329598)

<div class="topic-metadata">

**Author:** [@silentfilm](https://discuss.elastic.co/u/silentfilm)\
**Replies:** 2\
**Last updated:** [April 10, 2023, 7:22pm UTC](https://discuss.elastic.co/t/cant-get-filebeat-to-read-filestream/329598 "2023-04-10T19:22:13Z")

</div>

I'm trying to switch my filebeat "logs" streams to filestreams. I set up a really simple prospector file: --- filebeat.inputs: - type: filestream id: admintools paths: - '/home/geo/nba/6.3.5.1280/logs/admin-tool…

---

## [Pod container logs stop randomly](https://discuss.elastic.co/t/pod-container-logs-stop-randomly/325632)

<div class="topic-metadata">

**Author:** [@woodywoodsta](https://discuss.elastic.co/u/woodywoodsta)\
**Replies:** 5\
**Last updated:** [April 10, 2023, 5:20pm UTC](https://discuss.elastic.co/t/pod-container-logs-stop-randomly/325632 "2023-04-10T17:20:23Z")

</div>

Since upgrading to 8.6.1 (from 8.5.x), I'm finding that logs that are supposed to be collected via the Kubernetes Integration for an elastic agent in Fleet mode are stopping completely and randomly (as far as I can see). …

---

## [SSL alert number 47](https://discuss.elastic.co/t/ssl-alert-number-47/329599)

<div class="topic-metadata">

**Author:** [@nielarshi](https://discuss.elastic.co/u/nielarshi)\
**Replies:** 4\
**Last updated:** [April 10, 2023, 3:55pm UTC](https://discuss.elastic.co/t/ssl-alert-number-47/329599 "2023-04-10T15:55:30Z")

</div>

I am trying to setup Elasticsearch and Kibana 8.7.0 but facing issue with Kibana setup. It is failing with \[ERROR\]\[elasticsearch-service\] Unable to retrieve version information from Elasticsearch nodes. write EPROTO 14…

---

## [Help - Display correct document from multiple aggregation](https://discuss.elastic.co/t/help-display-correct-document-from-multiple-aggregation/329669)

<div class="topic-metadata">

**Author:** [@Santiago\_Lovera](https://discuss.elastic.co/u/Santiago_Lovera)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 3:18pm UTC](https://discuss.elastic.co/t/help-display-correct-document-from-multiple-aggregation/329669 "2023-04-10T15:18:35Z")

</div>

I need help please. I want to display a label in vega with information returned by one aggregation operation. I'm only looking for just 2 documents the minimum and the maximum for the log.json.sequence field. When I …

---

## [Elastic Agent v8.7.0, Filebeat UDP listener error](https://discuss.elastic.co/t/elastic-agent-v8-7-0-filebeat-udp-listener-error/329579)

<div class="topic-metadata">

**Author:** [@rowra](https://discuss.elastic.co/u/rowra)\
**Replies:** 5\
**Last updated:** [April 10, 2023, 2:55pm UTC](https://discuss.elastic.co/t/elastic-agent-v8-7-0-filebeat-udp-listener-error/329579 "2023-04-10T14:55:47Z")

</div>

Hi After upgrading from 8.6.2 to 8.7.0 this error happens all the time causing the agent/filebeat to crash and restart: nagent | {"log.level":"error","@timestamp":"2023-04-07T12:57:29.090+0200","message":"panic: runti…

---

## [Error 400 - Rejected by Elasticsearch](https://discuss.elastic.co/t/error-400-rejected-by-elasticsearch/329661)

<div class="topic-metadata">

**Author:** [@bobus](https://discuss.elastic.co/u/bobus)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 1:50pm UTC](https://discuss.elastic.co/t/error-400-rejected-by-elasticsearch/329661 "2023-04-10T13:50:46Z")

</div>

I'm trying to install the newest EFK stack on a Kubernetes cluster. ES and Kibana Helm charts are from Bitnami, while Fluentd is from Kokuwa (Bitnami's Fluentd simply doesn't work for me, if fails to link to ES). The ver…

---

## [Simple\_query\_string is not matching correctly](https://discuss.elastic.co/t/simple-query-string-is-not-matching-correctly/329656)

<div class="topic-metadata">

**Author:** [@jilson](https://discuss.elastic.co/u/jilson)\
**Replies:** 2\
**Last updated:** [April 10, 2023, 1:39pm UTC](https://discuss.elastic.co/t/simple-query-string-is-not-matching-correctly/329656 "2023-04-10T13:39:03Z")

</div>

I am trying the below query using simple\_query\_string to match customer\_id GET order-info/\_search { "query": { "simple\_query\_string": { "query": "1c0298d6-a911-5044-a904-6e848fb05eef", "fields": \["cust…

---

## [Treemap aggregation is not right](https://discuss.elastic.co/t/treemap-aggregation-is-not-right/329539)

<div class="topic-metadata">

**Author:** [@stramzik](https://discuss.elastic.co/u/stramzik)\
**Replies:** 4\
**Last updated:** [April 10, 2023, 12:27pm UTC](https://discuss.elastic.co/t/treemap-aggregation-is-not-right/329539 "2023-04-10T12:27:58Z")

</div>

Hi, When showing a 2 level tree map if the bottom level is averaged why does the top level sum the averages? {"Country": "India", "sample":1 , "State":"Karnataka" } {"Country": "India", "sample": 2, "State":"Delhi" }…

---

## [How to created multi field parsh message from snort](https://discuss.elastic.co/t/how-to-created-multi-field-parsh-message-from-snort/329637)

<div class="topic-metadata">

**Author:** [@wisnu\_adiputra](https://discuss.elastic.co/u/wisnu_adiputra)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 12:15pm UTC](https://discuss.elastic.co/t/how-to-created-multi-field-parsh-message-from-snort/329637 "2023-04-10T12:15:06Z")

</div>

Continuing the discussion from Grok pattern for snort alerts: 1/03-21:37:12.106096 \[\] \[1:249:8\] DDOS mstream client to handler \[\] \[Classification: Attempted Denial of Service\] \[Priority: 2\] {TCP} 172.16.0.5:61301 -\> 19…

---

## [How can I make logstash automatically send my information to elasticsearch?](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447)

<div class="topic-metadata">

**Author:** [@Raul\_dum](https://discuss.elastic.co/u/Raul_dum)\
**Replies:** 5\
**Last updated:** [April 10, 2023, 7:38am UTC](https://discuss.elastic.co/t/how-can-i-make-logstash-automatically-send-my-information-to-elasticsearch/329447 "2023-04-10T07:38:20Z")

</div>

Hi I was wondering if there is a method on how I could make logstash automatically send information to my elasticsearch.I have my config file : input { stdin {} } filter { grok { match =\> { "message" =\> "time=…

---

## [KQL formula in vega lite](https://discuss.elastic.co/t/kql-formula-in-vega-lite/328420)

<div class="topic-metadata">

**Author:** [@Nanditha](https://discuss.elastic.co/u/Nanditha)\
**Replies:** 2\
**Last updated:** [April 10, 2023, 8:08am UTC](https://discuss.elastic.co/t/kql-formula-in-vega-lite/328420 "2023-04-10T08:08:01Z")

</div>

Hi Team, I'm trying to plot a line graph using vega-lite. How to give KQL formulas in vega-lite. I used field called "claculate" but may be my syntax is wrong. Please help on creating line graph. { "$schema": "https:…

---

## [Self Managed ElasticSearch Cluster on AWS](https://discuss.elastic.co/t/self-managed-elasticsearch-cluster-on-aws/329645)

<div class="topic-metadata">

**Author:** [@shreyansh](https://discuss.elastic.co/u/shreyansh)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 7:48am UTC](https://discuss.elastic.co/t/self-managed-elasticsearch-cluster-on-aws/329645 "2023-04-10T07:48:35Z")

</div>

I am trying to setup a production ready self managed Elasticsearch cluster on AWS. The main reason for going self managed is that we want: Latest ES version (8.6+) Deploy in a specific VPC Install custom plugins We ar…

---

## [Elastic search update document , Java client-8.7](https://discuss.elastic.co/t/elastic-search-update-document-java-client-8-7/329644)

<div class="topic-metadata">

**Author:** [@Adarsh\_R\_K](https://discuss.elastic.co/u/Adarsh_R_K)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 7:25am UTC](https://discuss.elastic.co/t/elastic-search-update-document-java-client-8-7/329644 "2023-04-10T07:25:10Z")

</div>

How to update a document using elasticsearch Java client-8.7 , I could not find any documentation,All the avalilable ones are deprecated.

---

## [Map winlog.event\_data.param\* to text](https://discuss.elastic.co/t/map-winlog-event-data-param-to-text/329642)

<div class="topic-metadata">

**Author:** [@yohanwongso](https://discuss.elastic.co/u/yohanwongso)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 7:17am UTC](https://discuss.elastic.co/t/map-winlog-event-data-param-to-text/329642 "2023-04-10T07:17:24Z")

</div>

By default, Winlogbeat would map the winlog.event\_data.param\* as keyword. How to map the field to multi-fields keyword and text?

---

## [Clarification on cold/frozen state](https://discuss.elastic.co/t/clarification-on-cold-frozen-state/329575)

<div class="topic-metadata">

**Author:** [@QwerFact](https://discuss.elastic.co/u/QwerFact)\
**Replies:** 2\
**Last updated:** [April 10, 2023, 6:58am UTC](https://discuss.elastic.co/t/clarification-on-cold-frozen-state/329575 "2023-04-10T06:58:33Z")

</div>

Hiya, with the changes in version 8, the frozen tier has evolved. I was wondering about the differences between cold, cold fully-mounted and frozen and especially between open source and enterprise/platinum versions. M…

---

## [Custom Stacktrace for Transaction](https://discuss.elastic.co/t/custom-stacktrace-for-transaction/329160)

<div class="topic-metadata">

**Author:** [@AbhijithCV](https://discuss.elastic.co/u/AbhijithCV)\
**Replies:** 2\
**Last updated:** [April 10, 2023, 6:22am UTC](https://discuss.elastic.co/t/custom-stacktrace-for-transaction/329160 "2023-04-10T06:22:31Z")

</div>

Elasticsearch version: v8.1.2 APM Agent language and version: dotnet Agent v1.18.0 Hi, I have a requirement for fetching details of every function calls happened during execution of one transaction. The way I am curre…

---

## [Logstash pipeline error when processing a csv file](https://discuss.elastic.co/t/logstash-pipeline-error-when-processing-a-csv-file/329612)

<div class="topic-metadata">

**Author:** [@Ashutosh\_Vaidya](https://discuss.elastic.co/u/Ashutosh_Vaidya)\
**Replies:** 6\
**Last updated:** [April 10, 2023, 3:44am UTC](https://discuss.elastic.co/t/logstash-pipeline-error-when-processing-a-csv-file/329612 "2023-04-10T03:44:39Z")

</div>

Hello I am getting the below error when running the pipeline logstash conf file. Kindly let me know way to overcome this error student@elk:/$ sudo /usr/share/logstash/bin/logstash -f /etc/logstash/conf.d/csv-read-3.co…

---

## [Difference between KIBANA\_CA and KIBANA\_FLEET\_CA](https://discuss.elastic.co/t/difference-between-kibana-ca-and-kibana-fleet-ca/329634)

<div class="topic-metadata">

**Author:** [@OmFJ](https://discuss.elastic.co/u/OmFJ)\
**Replies:** 0\
**Last updated:** [April 10, 2023, 4:06am UTC](https://discuss.elastic.co/t/difference-between-kibana-ca-and-kibana-fleet-ca/329634 "2023-04-10T04:06:15Z")

</div>

Hello everyone. Currently i'm having trouble with applying elastic agent(managed by fleet) to my kubernetes environment. i think one of the related parameter is KIBANA\_CA and KIBANA\_FLEET\_CA. so far, i followed steps …

---

## [Elasticsearch](https://discuss.elastic.co/t/elasticsearch/329615)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 1\
**Last updated:** [April 10, 2023, 2:50am UTC](https://discuss.elastic.co/t/elasticsearch/329615 "2023-04-10T02:50:46Z")

</div>

where is the problem ? curl --cacert http\_ca.crt -u elastic https://localhost:9200 Invoke-WebRequest : Parameter cannot be processed because the parameter name 'u' is ambiguous. Possible matches include: -UseBasicParsi…

---

## [What is the point and purpose of ca\_trusted\_fingerprint?](https://discuss.elastic.co/t/what-is-the-point-and-purpose-of-ca-trusted-fingerprint/329623)

<div class="topic-metadata">

**Author:** [@jba](https://discuss.elastic.co/u/jba)\
**Replies:** 3\
**Last updated:** [April 9, 2023, 5:40pm UTC](https://discuss.elastic.co/t/what-is-the-point-and-purpose-of-ca-trusted-fingerprint/329623 "2023-04-09T17:40:38Z")

</div>

What is the point of adding the ca\_trusted\_fingerprint parameter to an logstash-output-elasticsearch section in an output filter? Is it purely to defend against a possible attack on DNS servers? Misconfiguration of the E…

---

## [Unable to perform airthmetic operations in ruby using logstash pipeline](https://discuss.elastic.co/t/unable-to-perform-airthmetic-operations-in-ruby-using-logstash-pipeline/329587)

<div class="topic-metadata">

**Author:** [@Sujith\_Nair](https://discuss.elastic.co/u/Sujith_Nair)\
**Replies:** 10\
**Last updated:** [April 9, 2023, 1:54pm UTC](https://discuss.elastic.co/t/unable-to-perform-airthmetic-operations-in-ruby-using-logstash-pipeline/329587 "2023-04-09T13:54:45Z")

</div>

Hi guys, I am facing an issue where i am trying to perform an airthmetic operation using ruby but in at the field section i am getting the same value not the subtracted value. event.set('\[d\]', (event.get('\[b\]').to\_f) -…

---

## [Integration sophos Firewall with elastic](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454)

<div class="topic-metadata">

**Author:** [@Ahmad\_Shrateh](https://discuss.elastic.co/u/Ahmad_Shrateh)\
**Replies:** 10\
**Last updated:** [April 9, 2023, 1:17pm UTC](https://discuss.elastic.co/t/integration-sophos-firewall-with-elastic/329454 "2023-04-09T13:17:26Z")

</div>

Dear there. Im trying to connect sophos firewall with elastic but i don't receive any logs. Im deployed an agent with sophos integration, and i followed the instructions on the elastic, i add my firewall ip instead …

---

## [ERROR: Failed to reset password for the \[elastic\] user](https://discuss.elastic.co/t/error-failed-to-reset-password-for-the-elastic-user/329618)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 1\
**Last updated:** [April 9, 2023, 7:44am UTC](https://discuss.elastic.co/t/error-failed-to-reset-password-for-the-elastic-user/329618 "2023-04-09T07:44:55Z")

</div>

Hi, I installed elasticsearch 8.7 on my windows server but on installing screen I did not get any prompt for my elasticsearch or kibana password, also when I tried to change the password I faced following error: ERROR:…

---

## [Logstash memory consumption and swap memory issues](https://discuss.elastic.co/t/logstash-memory-consumption-and-swap-memory-issues/329456)

<div class="topic-metadata">

**Author:** [@Ofek\_Agmon](https://discuss.elastic.co/u/Ofek_Agmon)\
**Replies:** 12\
**Last updated:** [April 9, 2023, 7:26am UTC](https://discuss.elastic.co/t/logstash-memory-consumption-and-swap-memory-issues/329456 "2023-04-09T07:26:56Z")

</div>

Hi all, I've been using logstash version 7.17.8 in docker, and for a while now trying to minimize its memory usage and swap usage, without much success. I have 2 file inputs and one gelf input, and 2 small filters. I …

---

## [Logstash running code](https://discuss.elastic.co/t/logstash-running-code/329408)

<div class="topic-metadata">

**Author:** [@sks](https://discuss.elastic.co/u/sks)\
**Replies:** 1\
**Last updated:** [April 5, 2023, 12:22pm UTC](https://discuss.elastic.co/t/logstash-running-code/329408 "2023-04-05T12:22:26Z")

</div>

Hyy, I am new to Elasticsearch . I am trying to send logfile from logstash to elasticsearch . for checking purspose i am running this config file as below vi logstash-simple.conf input { stdin { } } output { elasti…

---

## [Installing elasticsearch 8.6.2 on a windows server with ealsticserach 7.6.1](https://discuss.elastic.co/t/installing-elasticsearch-8-6-2-on-a-windows-server-with-ealsticserach-7-6-1/329281)

<div class="topic-metadata">

**Author:** [@hadi\_farzipour](https://discuss.elastic.co/u/hadi_farzipour)\
**Replies:** 7\
**Last updated:** [April 9, 2023, 5:01am UTC](https://discuss.elastic.co/t/installing-elasticsearch-8-6-2-on-a-windows-server-with-ealsticserach-7-6-1/329281 "2023-04-09T05:01:58Z")

</div>

In our company we have been using Elasticsearch 7.6.1 for two years, right now we need to update it to version 8.6.2, however, we can not move to version 8.6.2 immediately, we need first run Elasticsearch 8.6.2 beside th…

---

## [Geo\_shape query point in polygon runtime field for pre-indexed docs](https://discuss.elastic.co/t/geo-shape-query-point-in-polygon-runtime-field-for-pre-indexed-docs/329550)

<div class="topic-metadata">

**Author:** [@bchranko](https://discuss.elastic.co/u/bchranko)\
**Replies:** 3\
**Last updated:** [April 9, 2023, 12:48am UTC](https://discuss.elastic.co/t/geo-shape-query-point-in-polygon-runtime-field-for-pre-indexed-docs/329550 "2023-04-09T00:48:35Z")

</div>

I'm trying to create a geo\_shape query that will be used in a runtime field to tag a polygon 'id/name' to a point that it contains. I have two pre-indexed indexes: one for neighborhoods (polygon) and one for car crashe…

---

## [Configuration elasticsearch](https://discuss.elastic.co/t/configuration-elasticsearch/329506)

<div class="topic-metadata">

**Author:** [@Fatiha](https://discuss.elastic.co/u/Fatiha)\
**Replies:** 10\
**Last updated:** [April 8, 2023, 11:14pm UTC](https://discuss.elastic.co/t/configuration-elasticsearch/329506 "2023-04-08T23:14:51Z")

</div>

hi i want to Start Elasticsearch in Docker by this command : docker run --name es01 --net elastic -p 9200:9200 -it docker.elastic.co/elasticsearch/elasticsearch:8.7.0 but i have this probleme : ERROR: Elasticsearch di…

[Previous page](https://discuss.elastic.co/latest.md?page=716)

[Next page](https://discuss.elastic.co/latest.md?page=718)
